Privacy Policy
Lumis: Student Planner · Coral Code · Last updated September 1, 2026
Lumis is built by two students, and we treat your data the way we'd want ours treated: we collect what the app needs to work, we don't sell it, and you can delete it.
What we collect
- Account information — your email address and a securely hashed password, used to create and sign in to your account.
- Course content you upload — syllabi, lecture notes, slides, readings, and study materials. These are processed by AI to build your calendar, reminders, flashcards, quizzes, and study guides.
- Usage data — basic analytics about how the app is used (such as which features are opened and AI usage counts), associated with your account, used to fix problems and improve the app.
Your courses, assignments, notes, and study sessions are stored on your device. We do not collect your location, contacts, photos (other than syllabus images you choose to upload), or advertising identifiers.
The waitlist on this website
If you join the waitlist at lumisapp.org, we store the email address you enter, the school name if you provide one, whether you asked for a TestFlight beta invite, and the date you signed up. We also store a one-way hash of your IP address, which we use only to stop the form being spammed — it isn't used to identify you.
We use waitlist entries for one thing: emailing you about the Lumis beta and launch. It is not a marketing list we sell, rent, or share, and it isn't connected to an app account unless you create one. Ask us at privacy@lumisapp.org and we'll delete your entry — no account needed.
How your content is processed, and who receives it
Lumis sends the text of your course materials to OpenAI. When you upload a syllabus or generate study materials, the text is sent from your device to our server, and our server sends it to OpenAI (model gpt-4o-mini), which produces the result you asked for. This is the only third party that receives your course content.
What is sent to OpenAI:
- The text of syllabi and course documents you upload
- Your course names, assignment names, and due dates
- The questions you type into the Lumis AI assistant
What is not sent to OpenAI: your name, your email address, your password, your grades or GPA, your private notes, and your study-timer history. Images are never uploaded — a photographed syllabus is read into text on your device first, and only that text leaves your phone.
OpenAI processes this content solely to return your result. Under our agreement with OpenAI, submitted content is not used to train their models, and OpenAI is contractually required to provide protection of your data at least equivalent to that described in this policy. We do not sell or share your content for advertising.
You are asked before any of this happens. The first time you open Lumis, the app explains what is sent and who receives it, and asks permission. If you decline, the AI features are unavailable and nothing is transmitted. You can change your answer at any time in Profile → AI & Privacy.
Course Intelligence
Course Intelligence is a separate, opt-in feature. It is off unless you turn it on, and turning it off stops it immediately.
When it is on, the documents you upload are stored on our server in full — up to 60,000 characters of the original text per document, kept for as long as your account exists. Each document is also summarised by OpenAI into a short, course-level description (typical workload, exam timing, recurring topics). That summary is merged with summaries from other students taking the same course, at the same school, with the same instructor.
Courses are grouped using the school name you entered when you signed up, or, if you did not enter one, the domain of your email address. The merged summary contains no names, no email addresses, and nothing identifying who contributed to it.
Two things you should know before turning it on:
- Your uploaded documents are stored, not only processed in passing.
- If you delete your account, your stored documents are deleted with it, but the merged course-level summary is not. Once summaries from several students are combined, one person's contribution cannot be separated back out. That merged summary contains nothing personal to you.
Payments
Premium subscriptions are handled entirely by Apple through the App Store. We never see your payment details.
Deleting your data: you can delete your account and associated server data — including any documents stored through Course Intelligence — from within the app at Profile → Delete Account, or by emailing privacy@lumisapp.org from your account email. Deleting the app from your phone removes all on-device course data. The only thing retained is the merged, anonymous course summary described under Course Intelligence.
Data retention & security
Account and usage data are kept while your account is active and deleted on request. Documents stored through Course Intelligence are kept while your account is active and deleted with it; the merged, anonymous course summaries described above are retained. Waitlist entries are kept until launch or until you ask us to remove them. Passwords are stored only as salted hashes, and connections to our servers are encrypted in transit.
Children
Lumis is intended for college and high-school students aged 13 and up and is not directed at children under 13.
Changes
If our practices change, we'll update this page and the "last updated" date above, and material changes will be called out in the app.
Contact
Questions about privacy: privacy@lumisapp.org.